A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler. The manipulation leads to guessable captcha. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf. It is recommended to apply a patch to fix this issue.
{
"cna_assigner": "VulDB",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8546.json",
"cwe_ids": [
"CWE-287",
"CWE-804"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 785.0,
"function_hash": "276743334007744017902053742324071721802"
},
"id": "CVE-2025-8546-14b70833",
"signature_type": "Function",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"function": "mobile_login",
"file": "src/main/java/co/yiiu/pybbs/controller/api/IndexApiController.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 710.0,
"function_hash": "135191518287035039097528222664422836116"
},
"id": "CVE-2025-8546-299b1c67",
"signature_type": "Function",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"function": "login",
"file": "src/main/java/co/yiiu/pybbs/controller/api/IndexApiController.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 551.0,
"function_hash": "46327806450676146831567952480689153304"
},
"id": "CVE-2025-8546-49b8b211",
"signature_type": "Function",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"function": "sms_code",
"file": "src/main/java/co/yiiu/pybbs/controller/api/IndexApiController.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"126527644860276446337381431592199952523",
"273332153779206055292416274820885089374",
"38012844428037570167033565766038827976",
"191450388573280106713810687221831097816"
]
},
"id": "CVE-2025-8546-5aa743a6",
"signature_type": "Line",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"file": "src/main/java/co/yiiu/pybbs/controller/admin/IndexAdminController.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1241.0,
"function_hash": "60251454109088619925195501129293701462"
},
"id": "CVE-2025-8546-6aba916d",
"signature_type": "Function",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"function": "adminlogin",
"file": "src/main/java/co/yiiu/pybbs/controller/admin/IndexAdminController.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"328445987428086373017268624733112158001",
"109784412480779051337101059306053359340",
"241183476973406150198480825181775737780",
"86925429786499811427571154861111471647",
"226278739576943100060488722188727408412",
"37254563766456208976450029161654515289",
"241183476973406150198480825181775737780",
"86925429786499811427571154861111471647",
"337918087967121183035039124740189262223",
"276414785252259904576030703926613690877",
"330933201389344601391100972082813697836",
"176031941788024583912373069464867901678",
"121223203452740804777616182453163328966",
"260888233190188414777836060477734171937",
"241183476973406150198480825181775737780",
"176031941788024583912373069464867901678"
]
},
"id": "CVE-2025-8546-9ee7cb75",
"signature_type": "Line",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"file": "src/main/java/co/yiiu/pybbs/controller/api/IndexApiController.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 1090.0,
"function_hash": "67677807524966652656517846223949961432"
},
"id": "CVE-2025-8546-e0326531",
"signature_type": "Function",
"source": "https://github.com/atjiu/pybbs/commit/ecaf8d46944fd03e3c4ea05698f8acf0aaa570cf",
"target": {
"function": "register",
"file": "src/main/java/co/yiiu/pybbs/controller/api/IndexApiController.java"
}
}
]
"2026-07-22T00:05:52Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8546.json"